Trojan

About “IL:Trojan.MSILZilla.105645” infection

Malware Removal

The IL:Trojan.MSILZilla.105645 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What IL:Trojan.MSILZilla.105645 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the shellcode patterns malware family
  • Deletes executed files from disk
  • Yara detections observed in process dumps, payloads or dropped files

How to determine IL:Trojan.MSILZilla.105645?


File Info:

name: D9176921A6C8EAD5D143.mlw
path: /opt/CAPEv2/storage/binaries/109fc147c4e39e0c2aef596fa7eae6bc2bceefcc3ee3be5e69008a678333d8d2
crc32: FFB08DB4
md5: d9176921a6c8ead5d143b5dc9d90292b
sha1: 275741f82f4b9c244fd595a1cd878cd9e342869e
sha256: 109fc147c4e39e0c2aef596fa7eae6bc2bceefcc3ee3be5e69008a678333d8d2
sha512: bf5375a89e5a92b99f625ff8a456c1224003c6b9d33b5df98c499338d0b9d3c1c66bb7fbf172462e586762163c06ffb9aa0e2dfed9406a4c04d59ebd601dd197
ssdeep: 196608:Lypmh1JhAm7tYpA6fi0Zd7KEuybM9uu6wpOuqC:BxiDfi47D0pNN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C27612BBE15C253ED86E0A3145F35A604877BE22681A9C9E07F4360ECF734615E3B627
sha3_384: 6d5af1ef951d50276c7f59fb1b471840f6206147dbd290d00a99b8337c9128be80632421e55d91dadb2a245e22653ed3
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2023-02-15 14:54:16

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: My Company, Inc.
FileDescription: HUNTER CITY Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: HUNTER CITY
ProductVersion: 1.0.0.0
Translation: 0x0000 0x04b0

IL:Trojan.MSILZilla.105645 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.PowerShell.4!c
Elasticmalicious (moderate confidence)
DrWebTrojan.Siggen21.10427
MicroWorld-eScanIL:Trojan.MSILZilla.105645
FireEyeIL:Trojan.MSILZilla.105645
SkyhighBehavesLike.Win32.BadFile.vc
ALYacIL:Trojan.MSILZilla.105645
MalwarebytesGeneric.Malware/Suspicious
SangforTrojan.Win32.Agent.Vlyw
Cybereasonmalicious.1a6c8e
ArcabitIL:Trojan.MSILZilla.D19CAD [many]
SymantecTrojan.Gen.MBT
CynetMalicious (score: 99)
KasperskyUDS:Trojan.MSIL.PowerShell.gen
BitDefenderIL:Trojan.MSILZilla.105645
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.PowerShell!8.6469 (CLOUD)
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan.TR/Redcap.ftwpv
VIPREIL:Trojan.MSILZilla.105645
Trapminesuspicious.low.ml.score
EmsisoftIL:Trojan.MSILZilla.105645 (B)
VaristW32/ABRisk.TTGE-9016
AviraTR/Redcap.ftwpv
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Caynamer.A!ml
ZoneAlarmHEUR:Trojan.MSIL.PowerShell.gen
GDataIL:Trojan.MSILZilla.105645 (2x)
GoogleDetected
McAfeeArtemis!D9176921A6C8
Cylanceunsafe
IkarusTrojan.IL.MSILZilla
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)
alibabacloudTrojan:MSIL/PowerShell.gen

How to remove IL:Trojan.MSILZilla.105645?

IL:Trojan.MSILZilla.105645 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment